CVE-2017-7510
25.03.2019, 18:29
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | ovirt-engine | 4.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.